CVE-2026-93966 | aiyiyi121 SxDevOps 1.0/1.1 TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injection (Issue 16)
A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. It has been declared as problematic. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of the argument command leads to command injection.
This vulnerability is traded as CVE-2026-93966. The attack may be launched remotely. There is no exploit available.
It is advisable to implement a patch to correct this issue.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.VulDB Recent EntriesRead More